Open in app

Sign in

Write

Sign in

Elber Andre
Elber Andre

521 Followers

Home

About

Feb 17, 2020

BugBounty types — HTML injection via email

HTML injection é um ataque muito parecido com o Cross-site Scripting (XSS), enquanto no XSS o invasor pode injetar e executar códigos em Javascript, no ataque por injeção de HTML permite apenas a injeção de determinadas tags HTML. Já o HTML injection via email é baseado em substituir algumas informações…

Bug Bounty

3 min read

BugBounty types — HTML injection via email
BugBounty types — HTML injection via email
Bug Bounty

3 min read


Dec 12, 2019

Hack ’N’ Routers — Vulnerabilidades comuns em roteadores domésticos

Hello world, algumas pessoas já vem me pedindo a algum tempo para falar um pouco sobre algumas vulns e exploits para roteadores (acho que é para fins educacionais), então, hoje irei falar sobre algumas vulnerabilidades presentes em alguns modelos de roteadores domésticos, os quais na maioria das vezes seus donos/usuários…

Csrf

5 min read

Hack ’N’ Routers — Vulnerabilidades comuns em roteadores domésticos
Hack ’N’ Routers — Vulnerabilidades comuns em roteadores domésticos
Csrf

5 min read


Apr 27, 2019

Broken Access: Posting to Google private groups through any user in the group

(My main goal in this post is to show tricks for bug hunters, today I’m showing Email Spoofing) These days I reported a bug in Google Groups to Google, but received the following response: “Thanks for reporting! We think the issue might not be severe enough for us to…

Email

4 min read

Broken Access: Posting to Google private groups through any user in the group
Broken Access: Posting to Google private groups through any user in the group
Email

4 min read


Apr 25, 2019

SSTI: Bypass in a hard place, Fort Knox — ASIS Quals 2019

Apresentação: Vamos imaginar uma situação onde estamos analisando alguma aplicação que aparentemente esta vulnerável a Server Side Template Injection (SSTI), mas alguns de nossos payloads não estão retornando resposta, também suspeitamos que por trás de tudo isso possa ter um firewall barrando algumas de nossas solicitações, esse foi o caso do…

Ssti

3 min read

SSTI: Bypass in a hard place, Fort Knox — ASIS Quals 2019
SSTI: Bypass in a hard place, Fort Knox — ASIS Quals 2019
Ssti

3 min read


Apr 9, 2019

SSRF Tips: SSRF/XSPA in Microsoft’s Bing Webmaster Central

Today I’m going to talk about a trick that might be useful for BugHunters. While I was looking for a few things about BugBounty, I found a report where the author talked about an SSRF which he had found in Bing’s Webmaster Central, and reported to Microsoft. In the Bug it describes…

DNS

2 min read

SSRF Trick: SSRF/XSPA in Microsoft’s Bing Webmaster Central
SSRF Trick: SSRF/XSPA in Microsoft’s Bing Webmaster Central
DNS

2 min read


Feb 17, 2019

$1.000 SSRF in Slack

Before I start, I have two important tips for anyone starting in the world of BugBounty. 1: Always check previous reports, you may know some bypass that may work in that situation, or you can learn something new. 2: If you like content about Bug Bounty or other hacking related…

Slack

4 min read

$1.000 SSRF in Slack
$1.000 SSRF in Slack
Slack

4 min read


Feb 14, 2018

Router exploit: Getting Wireless Password and Administrator Session Without Being Connected on the Same Network.

[CVE-2017–14219] XSS IN INTELBRAS ROUTER WRN 240. Follow-me: https://twitter.com/Elber333 How it started: Have I been trying to hack my router for some time, reasons? Just missing what to do, and sometimes lack of internet too, this was from attempts to upload with modified firmware to attempts to insert codes on the page by…

JavaScript

4 min read

Router exploit: Getting Wireless Password and Administrator Session Without Being Connected on the…
Router exploit: Getting Wireless Password and Administrator Session Without Being Connected on the…
JavaScript

4 min read


Feb 8, 2018

Uploader bypass: Obtendo XSS em ‘imagem . jpg’

Como eu consegui burlar um sistema de upload e obter um XSS em uma imagem. Dias atrás eu vinha buscando por sites no Hackerone no intuito de encontrar alguma vulnerabilidade em alguns deles e em troca, ganhar pontos de reputação. Como sou iniciante, decidi começar com a General motors, em…

Xss

2 min read

Uploader bypass: Obtendo XSS em ‘imagem . jpg’
Uploader bypass: Obtendo XSS em ‘imagem . jpg’
Xss

2 min read

Elber Andre

Elber Andre

521 Followers

Pentester , CTF player, Bug Hunter & Security Researcher \nTwitter: https://twitter.com/elber333

Following
  • Ataide Junior

    Ataide Junior

  • Sai Krishna Kothapalli

    Sai Krishna Kothapalli

  • Joao Vitor Lopes

    Joao Vitor Lopes

  • Renato Alencar

    Renato Alencar

  • TheZakMan

    TheZakMan

See all (55)

Help

Status

About

Careers

Blog

Privacy

Terms

Text to speech

Teams